Fetching from the wire…
Public story · 2026-08-07 · high
GitHub found over half its new npm malware advisories were echoes of its own past reports, not fresh OpenSSF findings.
Why now: GitHub published the ecosystem expansion and the npm dedup finding together in an August 6 security blog post.
GitHub extended its Advisory Database to eight package ecosystems on August 6, wiring in OpenSSF's malicious-packages repository, per its security blog.
Developers on seven more ecosystems now get automatic warnings drawn from OpenSSF's 15,000-plus malware reports, alongside the npm users GitHub already covered.
The database now covers PyPI, Maven, RubyGems, NuGet, Go, crates.io, and Composer, alongside npm.
Malware advisories auto-publish without human review, so GitHub built the ingestion defensively. Per-run batch caps halt an entire run rather than let a partial import through. Each advisory's provenance is tracked to the exact upstream commit, and rollback happens at the batch level when something looks off.
Further down the post is the more interesting number. GitHub's team deduplicated new npm reports against OpenSSF's feed and found more than half had started as GitHub's own prior advisories.
That's a feedback loop hiding inside a security data source. A chunk of what looks like independent confirmation from OpenSSF is really GitHub's own data, reflected back at itself and counted again. GitHub caught it because it ran a dedup check before merging the feeds. Most tools that cite OpenSSF, or that cite GitHub, have no reason to run that check.
Worth watching is whether GitHub publishes dedup rates for the other seven ecosystems. npm might turn out to be the outlier, or the norm.
Each link below shares sources, entities, or timing with this story.
Shared entities / Same source domain / Earlier coverage
Both cover GitHub, NuGet, PyPI, RubyGems; reported by the same outlet (github.blog); earlier GitHub coverage from 2026-04-02.
Cursor released Composer / Shared entities / Earlier coverage / Tension
Linked by a graph relationship (Cursor released Composer); both cover Composer, GitHub; earlier Composer coverage from 2026-06-27.
Cursor Start uses Composer / Shared entity: Composer / Earlier coverage
Linked by a graph relationship (Cursor Start uses Composer); both cover Composer; earlier Composer coverage from 2026-07-28.
Cursor released Composer / Shared entities / Earlier coverage
Linked by a graph relationship (Cursor released Composer); both cover August, GitHub; earlier August coverage from 2026-08-04.
Linked by a graph relationship (Cursor released Composer); both cover Composer, GitHub; earlier Composer coverage from 2026-07-11.
Shared entities / Earlier coverage
Both cover GitHub, PyPI, RubyGems; earlier GitHub coverage from 2026-06-13.
Cursor released Composer / Shared entity: GitHub / Same source domain / Earlier coverage
Linked by a graph relationship (Cursor released Composer); both cover GitHub; reported by the same outlet (github.blog).
Linked by a graph relationship (Cursor released Composer); both cover GitHub; reported by the same outlet (github.blog).